"does pfsense intercept dns traffic if clients set their own DNS servers?"

No but my ISP does this all the time and forces me to use pages that they have cached even when i use OpenDNS for the upstream server.

Bit rude of them when I have elected not to use their DNS server but this means that they are also having to isue fake SSL certificates too and are doing a Man-in-Middle to speed up pages and to save themselves money on the upstream bandwidth.